Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

BYOD for Small Businesses: The Risks of Personal Devices and a Sensible Policy

In short

Bring Your Own Device (BYOD) — staff using personal phones and laptops for work — is common in small firms and often unavoidable. It's convenient and cheap, but it scatters company data across devices you don't control. A short, clear BYOD policy plus a few basic safeguards lets you get the benefits without leaving the back door open.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Convenient, cheap — and quietly risky

Ask a small business how staff pick up work email or check a customer’s details on the move, and the honest answer is usually “on their own phone”. Bring Your Own Device, or BYOD, is everywhere: it saves buying hardware, staff already know their own kit, and it just happens naturally. For many firms it isn’t even a decision — it’s simply what people do.

The problem is that the moment company data lands on a device you don’t own, you lose sight of it. That customer’s phone number, that invoice attachment, that saved password — it’s now sitting on a phone that might have no screen lock, an out-of-date operating system, a teenager playing games on it, or a habit of connecting to dodgy café Wi-Fi. You’re still legally responsible for that data under UK GDPR, but you have very little control over it. This article explains the real risks in plain terms and gives you a sensible policy you can actually put in place.

What actually goes wrong with personal devices

BYOD risks aren’t dramatic hacks; they’re everyday, mundane things:

  • Lost or stolen phones — a device with no lock screen or encryption hands over everything on it. Phones get left in taxis and on train seats every day.
  • No separation of work and home — company files mixed in with personal photos, family members using the same device, work data backed up to a personal cloud account you know nothing about.
  • Out-of-date software — personal devices rarely get patched as promptly as business ones, leaving known holes open.
  • Data that never comes back — when someone leaves, whatever’s on their personal device tends to stay there.
  • Weak or reused passwords — the same password protecting a work account and a dozen personal ones, ready to be exposed in the next breach.

None of these needs a sophisticated criminal. They just need a bit of bad luck and no plan.

The two honest options

There are really only two respectable positions. The first is issuing company-owned devices you fully control — cleaner and safer, but it costs money many small firms don’t have. The second is BYOD done properly: personal devices allowed, but under a clear set of rules with a few technical safeguards.

The one option that isn’t acceptable is the accidental status quo most firms drift into — unmanaged BYOD, where personal devices touch company data with no policy, no controls and no way to switch off access. If that describes you, you’re carrying risk you can’t see and couldn’t measure if asked.

The one option that isn’t acceptable is the accidental status quo most firms drift into — unmanaged BYOD, where personal devices touch company data with no policy, no controls and no way to switch off access.

A sensible BYOD policy, in plain terms

A good policy is short enough that people read it and clear enough that they can follow it. Cover these points:

1. Which devices and who. State that staff may use personal devices for work only if they meet the conditions below, and that access can be withdrawn if they don’t.

2. Basic device hygiene. Every device used for work must have a screen lock (PIN, fingerprint or face), automatic updates switched on, and up-to-date software. These are free and take minutes.

3. Protect the accounts, not just the device. Require multi-factor authentication on work email and systems, so a stolen password alone isn’t enough to get in. This is the single highest-value control you can insist on.

4. Sort out passwords. Weak, reused passwords are the thread that unravels everything. Ask staff to use a password manager so every work login is strong and unique, and none of it lives in a notes app or on a sticky label. A tool like Proton Pass works across personal phones and laptops and keeps work credentials separate and encrypted — a practical fit for BYOD. If you’re weighing up options, our guide to the best password managers for small businesses walks through the choices.

5. Keep work data in the right place. Company files belong in company systems — your Microsoft 365 or shared drive — not saved locally or copied into personal cloud accounts. The goal is that work data stays in apps and accounts you can switch off centrally.

6. Public Wi-Fi and travel. Discourage sensitive work over open networks; where staff regularly work on the move, a reputable VPN such as Proton VPN protects data on untrusted connections.

7. Lost devices and leavers. Staff must report a lost or stolen device immediately. And be explicit about what happens when someone leaves: their access is revoked centrally, so nothing depends on them remembering to delete files.

Make leaving as controlled as joining

That last point deserves emphasis, because it’s where BYOD most often fails. If company email and files live inside managed accounts, offboarding is a matter of flipping a switch — access gone, data no longer reachable, device or not. If they live loose on a personal phone, you’re trusting an ex-employee’s goodwill. Design your setup so the switch exists.

Getting the balance right

BYOD isn’t reckless — done properly, it’s a reasonable, cost-effective way to work, and it’s part and parcel of modern remote and flexible working. The aim isn’t to spy on anyone’s personal phone or lock it down to the point of uselessness. It’s to draw a sensible line: staff get the convenience of their own devices, and the business keeps control of its own data.

Most of the safeguards above are free or inexpensive and can be rolled out in an afternoon. The hard part is usually knowing where to start and making sure nothing’s missed. If you’d like a straightforward BYOD policy tailored to how your team actually works — and the cyber-security basics to back it up — get in touch and we’ll help you put it in place without the drama.

Frequently asked questions

Is it legal for staff to use their own devices for work?

Yes, there's no law against BYOD. But you remain responsible under UK GDPR for personal data your business handles, wherever it sits — including on an employee's phone. So if a member of staff has customer details in their email or messages on a personal device, that data is still your responsibility to protect. A written policy and basic controls are how you meet that duty.

Can we force staff to install software on their personal phones?

You can set conditions for accessing company systems, but you can't treat someone's personal device like company property. The practical middle ground is to require sensible, proportionate protections — a screen lock, up-to-date software, multi-factor authentication — and to keep company data inside managed apps rather than trying to control the whole device. Be clear and reasonable, agree it in writing, and most staff are happy to comply.

What happens to company data when someone leaves?

This is one of BYOD's biggest weak spots. If work email, files or messages live on a personal phone with no way to remove them, that data can walk out of the door with the employee. The fix is to keep company data within apps or accounts you can revoke access to, so that on their last day you switch off their access centrally rather than relying on them to delete things themselves.

Isn't it safer to just give everyone company devices?

Company-owned devices are easier to control and are the cleaner option where budgets allow, especially for staff handling sensitive data. But they cost money and many small firms can't kit everyone out. BYOD done properly — with a policy, MFA and managed access — is a reasonable middle ground. The wrong answer is unmanaged BYOD, where personal devices access company data with no rules at all.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.